Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Sandworm hackers target IT pros with trojanized WireGuard VPN client

    August 11, 2026

    No Bosses: Ancient Engineering Marvel Was Built Without Rulers, Study Suggests

    August 11, 2026

    The OSINT Newsletter – Issue #118

    August 11, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Sandworm hackers target IT pros with trojanized WireGuard VPN client
    News

    Sandworm hackers target IT pros with trojanized WireGuard VPN client

    adminBy adminAugust 11, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Sandworm hackers target IT pros with trojanized WireGuard VPN client

    Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May.

    A report from the Ukrainian Computer Emergency Response Team (CERT) details a social engineering campaign attributed to UAC-0145, which is believed to be a sub-cluster of Sandworm (APT44). In the campaign, the threat actor targets victims while posing as IT companies and recruiters.

    The agency says that the attacker studies the targets’ resumes uploaded on job sites and then initiates direct contact.

    image

    Conversations are then moved to Telegram to arrange a video interview over Zoom. During the interview, which is conducted in English, the candidates receive mock technical assignments that require them to connect to a corporate VPN.

    Conversations with a supposed recruiter
    Conversations with a supposed recruiter
    Source: CERT-UA

    In one case that CERT-UA observed, the attacker impersonated the international IT firm Sopra Steria using seemingly legitimate email addresses similar to the company’s office in Bulgaria.

    “In parallel, additional instructions for the technical interview are sent via email, including configuration files for connecting to a ‘corporate’ VPN using Wireguard (Linux/Windows) to supposedly perform test tasks,” CERT-UA says.

    Email-download
    Malicious emails and VPN download link
    Source: CERT-UA

    The downloaded file is configured to produce a fake error. The attackers then prompt the victim to download a modified WireGuard-based client called “SopraVPN” from SourceForge.

    The SourceForge page even includes a link to soprasteria-bg[.]com to increase credibility, although the domain has no connection to the legitimate company.

    The trojanized client supports a malicious, nonstandard “SymmetricKey” configuration option that decrypts and executes embedded PowerShell code.

    On Windows, the malicious command creates a scheduled task and downloads an additional payload from the Internet.

    On Linux, it uses cURL to retrieve another executable from attacker-controlled infrastructure through the VPN.

    CERT-UA also noted that WireGuard’s standard Base64 decoding was replaced in the trojanized version with a custom, dynamically generated Base64 alphabet, which renders key strings unreadable with standard decoders and protects the PowerShell code from analysis.

    The Ukrainian cyber agency advises telecommunications providers and IT companies whose staff are targeted by this campaign to restrict corporate resource access to managed, continuously monitored devices protected by EDR, including when employees use personal equipment.

    APT44 is notorious for targeting critical infrastructure and government entities both in Ukraine, and also in other countries.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleNo Bosses: Ancient Engineering Marvel Was Built Without Rulers, Study Suggests
    admin
    • Website

    Related Posts

    News

    No Bosses: Ancient Engineering Marvel Was Built Without Rulers, Study Suggests

    August 11, 2026
    News

    The OSINT Newsletter – Issue #118

    August 11, 2026
    News

    Mozilla updates GPG signing key for Firefox releases after exposure

    August 11, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202639 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202639 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views
    Our Picks

    Sandworm hackers target IT pros with trojanized WireGuard VPN client

    August 11, 2026

    No Bosses: Ancient Engineering Marvel Was Built Without Rulers, Study Suggests

    August 11, 2026

    The OSINT Newsletter – Issue #118

    August 11, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.